Metrics
Affected Vendors & Products
Solution
IBM strongly recommends addressing the vulnerability now. ProductsVersion range Remediation InstructionsIBM Fusion2.2.0 - 2.10.1Upgrade to IBM Fusion 2.11.0. See the README https://www.ibm.com/support/pages/node/7242341 for instructions..IBM Fusion HCI2.2.0 - 2.10.0Upgrade to IBM Fusion HCI 2.11.0. See the README https://www.ibm.com/support/pages/node/7242340 for instructions.IBM Fusion HCI for watsonx2.8.2 - 2.10.0Upgrade to IBM Fusion HCI for watsonx 2.11.0. See README https://www.ibm.com/support/pages/node/7242340 for instructions.
Workaround
No workaround given by the vendor.
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7244646 |
![]() ![]() |
Thu, 11 Sep 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10.0 uses insecure default configurations that could expose AMQStreams without client authentication that could allow an attacker to perform unauthorized actions. | |
Title | IBM Fusion insecure default configuration | |
First Time appeared |
Ibm
Ibm storage Fusion Ibm storage Fusion Hci Ibm storage Fusion Hci For Watsonx |
|
Weaknesses | CWE-1188 | |
CPEs | cpe:2.3:a:ibm:storage_fusion:2.10.1:*:*:*:*:*:*:* cpe:2.3:a:ibm:storage_fusion:2.2.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:storage_fusion_hci:2.10.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:storage_fusion_hci:2.2.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:storage_fusion_hci_for_watsonx:2.10.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:storage_fusion_hci_for_watsonx:2.8.2:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibm
Ibm storage Fusion Ibm storage Fusion Hci Ibm storage Fusion Hci For Watsonx |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-09-11T20:44:06.696Z
Reserved: 2025-04-15T21:16:41.802Z
Link: CVE-2025-36222

No data.

Status : Received
Published: 2025-09-11T21:15:34.350
Modified: 2025-09-11T21:15:34.350
Link: CVE-2025-36222

No data.

No data.